{"provider_url":"https://hatena.blog","categories":["Bug Report"],"height":"190","title":"Unveiling Privilege Escalation and Sensitive Data Exposure across the Domain \u304b\u3089\u5b66\u3076","provider_name":"Hatena Blog","type":"rich","author_url":"https://blog.hatena.ne.jp/U3nerd/","author_name":"U3nerd","blog_title":"The light of hope to the other side of the tunnel - Kotsu Kotsu To -","description":"\u30bd\u30fc\u30b9\uff1a javroot.medium.com \u8106\u5f31\u6027\uff1aOAuth \u8a33\uff1a Burp Suite\u3092\u958b\u59cb\u3057\u3066\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30ad\u30e3\u30d7\u30c1\u30e3\u3059\u308b\u969b\u306b\u3001\u30e1\u30a4\u30f3\u30c9\u30e1\u30a4\u30f3\u3067\u30ed\u30b0\u30a4\u30f3\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u78ba\u7acb\u3057\u307e\u3057\u305f\u3002 \u30b7\u30b9\u30c6\u30e0\u306b\u30a2\u30af\u30bb\u30b9\u3057\u305f\u5f8c\u3001\u30e1\u30a4\u30f3 \u30c9\u30e1\u30a4\u30f3\u306e\u591a\u6570\u306e\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3067\u306e\u30c7\u30fc\u30bf\u53d6\u5f97\u3092\u8a31\u53ef\u3059\u308b OAuth \u30c8\u30fc\u30af\u30f3\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002 \u305f\u3060\u3057\u3001\u73fe\u5728\u3001\u8ffd\u52a0\u306e\u30da\u30fc\u30b8\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u6a5f\u80fd\u304c\u3042\u308a\u307e\u305b\u3093\u3002 \u3057\u304b\u3057\u3001\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u3082\u3046\u4e00\u5ea6\u8a73\u3057\u304f\u691c\u8a0e\u3057\u3066\u307f\u308b\u3053\u3068\u306b\u3057\u305f\u3068\u3053\u308d\u3001Web\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u3064\u3044\u3066\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u6c17\u3065\u304d\u307e\u3057\u305f\u3002 OAuth \u30c8\u30fc\u30af\u30f3\u306f API \u30c9\u30e1\u30a4\u30f3\u5185\u3067\u751f\u6210\u3055\u308c\u307e\u3059 \u6b21\u306b\u3001\u30b5\u30d6\u30d5\u30a1\u30a4\u30f3\u30c0\u30fc\u3067\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u3092\u63a2\u3059\u2026","url":"https://u3nerd.hatenablog.com/entry/2023/12/15/092619","version":"1.0","width":"100%","published":"2023-12-15 09:26:19","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fu3nerd.hatenablog.com%2Fentry%2F2023%2F12%2F15%2F092619\" title=\"Unveiling Privilege Escalation and Sensitive Data Exposure across the Domain \u304b\u3089\u5b66\u3076 - The light of hope to the other side of the tunnel - Kotsu Kotsu To -\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","image_url":"https://cdn-ak.f.st-hatena.com/images/fotolife/U/U3nerd/20231215/20231215091340.png","blog_url":"https://u3nerd.hatenablog.com/"}